{{- if .Values.rbacManager.deploy }}
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole
metadata:
  name: {{ template "crossplane.name" . }}:allowed-provider-permissions
  labels:
    app: {{ template "crossplane.name" . }}
    {{- include "crossplane.labels" . | indent 4 }}
aggregationRule:
  clusterRoleSelectors:
  - matchLabels:
      rbac.crossplane.io/aggregate-to-allowed-provider-permissions: "true"
{{- end}}